Linuxsecurity Critical DoS Vulnerabilities in python-ujson Affect Fedora Users
Article Content
- •CVE-2026-32875 and CVE-2026-32874 are critical DoS vulnerabilities in python-ujson.
- •Affected systems include Fedora 42 and 43, requiring immediate updates.
- •Users should upgrade to python-ujson version 5.12.0 to mitigate risks.
On March 20, 2026, two critical vulnerabilities (CVE-2026-32875 and CVE-2026-32874) were published affecting the python-ujson library, which is widely used for JSON encoding and decoding in Python applications. These vulnerabilities can lead to denial of service (DoS) attacks through a buffer overflow and infinite loop caused by large indent parameters during JSON serialization. Users of Fedora 42 and 43 are particularly affected, with updates released to address these issues. The vulnerabilities were reported to be exploitable, making it essential for users to apply the latest updates. The updates include version 5.12.0 of python-ujson, which fixes the identified issues. Users are advised to upgrade using the 'dnf' package manager to mitigate the risks associated with these vulnerabilities. The current status is that the vulnerabilities are patched, but users must ensure they have updated their systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Fedora and CVE-2026-32874 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…